frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

BMW ConnectedDrive lets me control my returned rental car (Sixt)

5•derturm666•4h ago
Last week I rented a BMW from Sixt (Italy).

The default rental driver profile had Bluetooth disabled, so I created my own BMW ID, paired it with the car, removed the existing profile, and even triggered software updates.

When returning the car, I told the Sixt representative that I had linked my BMW ID — they assured me that the vehicle would be reset.

Today — just before deleting the “My BMW” app — I checked out of curiosity.

Surprise: I still had full remote access:

- live location tracking

- remote lock/unlock

- honking (hehe)

- turn lights on/off

At this point, the car was presumably already rented to someone else. I could track the new renter’s location and remotely interact with the car.

IMO, this exposes a serious security/privacy issue:

- BMW ConnectedDrive still had my account associated to the vehicle VIN

- Sixt’s reset procedure didn’t revoke my BMW ID access

I suspect this may not be limited to Sixt, but could affect other rental fleets using ConnectedDrive if proper backend disassociation isn’t done.

BMW allows fleet integrations via ConnectedDrive Fleet Services, but I wonder how many rental cars globally still have previous renters’ IDs attached.

Comments

7bit•3h ago
If you want to invest the time you can report this DPA violation. They are obliged to reset the car to ensure the next renters privacy, especially if you told them. Violations can be expensive and it is generally a good idea to report so the big corps keep getting reminded that privacy is an important right of their customers.

Gemma 3n

https://deepmind.google/models/gemma/gemma-3n/
1•tosh•3m ago•0 comments

Why Public Transit Helps Young People Get Work (2018)

https://scholars.org/contribution/why-public-transit-helps-young-people-get-work
1•robtherobber•4m ago•0 comments

We Can Just Measure Things

https://lucumr.pocoo.org/2025/6/17/measuring/
1•tosh•9m ago•0 comments

pacersdk: Python SDK for accessing the Pacer API

https://pacersdk.org/
1•mcpcpc•11m ago•1 comments

Ask HN: What are some ways the internet is being used for good?

1•ronbenton•13m ago•0 comments

Show HN: I made Duolingo but for screen time

https://lockedin.tech/
1•cchc•15m ago•1 comments

Made a CIAM hub – what should we add?

https://ssojet.com/ciam-101
1•andy89•15m ago•1 comments

Cursor Launches Ultra Plan

https://forum.cursor.com/t/working-with-the-model-providers-to-launch-ultra/104530
2•johanyc•19m ago•0 comments

KDE Plasma 6.4 Released

https://kde.org/announcements/plasma/6/6.4.0/
1•jlpcsl•20m ago•0 comments

The Two Cultures

https://nickmccleery.com/posts/10-the-two-cultures/
1•physicsguy•22m ago•0 comments

Thinking Was Real. The Illusion Was Yours

https://b0a04gl.site/blog/thinking-was-real-illusion-was-yours
1•b0a04gl•24m ago•0 comments

Has Signal usage collapsed? It seems so

http://www.seriousaboutech.com/2025/06/has-signal-usage-collapsed-it-seems-so.html
1•janandonly•26m ago•0 comments

Testing a Robust Netcode with Godot

https://studios.ptilouk.net/little-brats/blog/2024-10-23_netcode.html
1•smig0•27m ago•0 comments

"Microsoft Locked My Account – I Lost 30 Years of Photos and Work"

https://old.reddit.com/r/pcmasterrace/comments/1ldef4p/microsoft_locked_my_account_i_lost_30_years_of/
6•bundie•28m ago•0 comments

Building US Citizenship Test Flashcard Prep Tool

https://den.dev/blog/us-citizenship-test/
1•furkansahin•30m ago•0 comments

Show HN: I solved the biggest problem with YouTube learning

https://www.notetubeai.com/
1•AzharKhann•33m ago•0 comments

From Prompt to Product: A Comparison of Full-Stack App Generators

https://eclecticmind.org/posts/from-prompt-to-product-a-comparison-of-full-stack-app-generators
1•fredrikappelros•33m ago•0 comments

Trump takes down Trump Mobile coverage map that includes "Gulf of Mexico"

https://www.neowin.net/news/trumps-team-takes-down-trump-mobile-coverage-map-that-includes-gulf-of-mexico/
1•bundie•33m ago•0 comments

Show HN: SnapSys – A lightweight CLI tool to capture system hardware snapshots

https://github.com/MarcusMJV/snapsys
1•MarcusMJV•37m ago•0 comments

Building the World's Most Over-Engineered Personal Blog

https://ganis.net/okblog
1•ganiszulfa•37m ago•0 comments

Agentic AI Platform for Enterprise IAM

https://embesozzi.medium.com/agentic-ai-platform-for-enterprise-iam-secure-agent-driven-governance-based-on-zero-trust-289a52f42790
1•emreb•42m ago•0 comments

Animating zooming using CSS: transform order is important sometimes

https://jakearchibald.com/2025/animating-zooming/
2•jaffathecake•46m ago•0 comments

Encryption on the menu at EU Justice Ministers debate

https://www.euractiv.com/section/tech/news/exclusive-encryption-on-the-menu-at-eu-home-affairs-ministers-debate/
2•nickslaughter02•46m ago•0 comments

Measuring the weight of an airplane – while it's flying [video]

https://www.youtube.com/watch?v=hnvtstq3ztI
1•Titan2189•50m ago•0 comments

The Silurian Hypothesis (2018)

https://arxiv.org/abs/1804.03748
2•ipnon•50m ago•0 comments

Run natural language lead enrichment inside gSheets

https://www.linkup.so/linkup-googlesheets
1•kyeliq•50m ago•0 comments

Idea to Revenue in 4 Days

https://sigurg.com/post/product/product-speedrun/
1•matthewolfe•56m ago•0 comments

Chicken Sexing and Perceptual Learning as a Path to Expertise

https://commoncog.com/chicken-sexing-and-perceptual-learning-as-a-path-to-expertise/
1•eamag•1h ago•0 comments

iOS 26 Will Let You Add Your U.S. Passport to Wallet for Identity Verification

https://www.macrumors.com/2025/06/10/ios-26-passport-wallet-identity-verification/
2•angryGhost•1h ago•0 comments

Type Inference Zoo

https://zoo.cuichen.cc/
1•todsacerdoti•1h ago•0 comments